Briefing

Gravity SMTP Security Breach CVE‑2026‑4020 Exposes API Keys

security
by /u/mortndk · CVE-2026-4020

Patch Gravity SMTP to version 2.1.5 or later immediately to fix CVE‑2026‑4020 and rotate any exposed API keys.

What to do now

Patch Gravity SMTP to version 2.1.5 or later immediately and rotate any exposed API keys.

Summary

Gravity SMTP, a paid plugin for Gravity Forms, released version 2.1.5 with security enhancements. The update patches CVE‑2026‑4020, a vulnerability that exposed a mock‑data API endpoint. The endpoint dumps all plugin settings, including API keys, and was present in earlier versions. The changelog did not disclose the severity of the exploit, which caused a SendGrid account to be closed due to leaked keys. The plugin’s security breach was discovered by a user who noticed the vulnerability. The CVE allows attackers to read sensitive configuration data. The plugin’s developers recommend updating to 2.1.5 or later immediately. Users should also rotate any compromised API keys.

Key changes

  • Gravity SMTP 2.1.5 patches CVE‑2026‑4020 vulnerability.
  • CVE exposed mock‑data API endpoint that dumps plugin settings and API keys.
  • Changelog omitted severity disclosure of the exploit.
  • SendGrid account closed due to leaked API keys from the vulnerability.
  • Users must rotate compromised API keys after patching.

Affects

wp-customers

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting